Junglewise Threat Intelligence

CVE-2026-28578: Google Android improper input validation in DevicePolicyManagerService

CVE-2026-28578 · Severity: info · CVSS 5.5 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android Device Policy Manager, which handles corporate security settings and device restrictions, could allow a local attacker to cause a denial of service. This means an app or local user could potentially crash the system service or cause it to stop functioning correctly, disrupting device management and stability. No special permissions or user interaction are required to trigger this issue.

Technical details

An improper input validation vulnerability exists in multiple functions within DevicePolicyManagerService.java in the Android Framework. This flaw can lead to a desynchronization between the service's runtime state and its persistent storage. A local attacker can exploit this to trigger a denial of service (DoS) condition without requiring additional execution privileges or user interaction. The issue affects Android versions 14, 15, and 16, and is addressed in the June 2026 security patch level.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References

Related threats